STIGQter STIGQter: STIG Summary: Video Services Policy STIG Version: 1 Release: 11 Benchmark Date: 24 Apr 2020:

Access control measures must be implemented for all conferences hosted on a centralized MCU appliance.

DISA Rule

SV-18893r2_rule

Vulnerability Number

V-17719

Group Title

RTS-VTC 5020

Rule Version

RTS-VTC 5020.00

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implement access control measures for all conferences hosted on a centralized MCU appliance as follows:
- Only authorized endpoints are permitted to access an MCU
- Only authorized users are permitted to access/join a conference. Authorization is pre-configured on the MCU access control system and is based on validated need-to-know as well as security clearance if applicable.

Note: this applies to standing, scheduled one-time, and non-scheduled ad hoc conferences.

Check Contents

Review site documentation to confirm control measures are implemented for all conferences hosted on a centralized MCU appliance as follows:
- Only authorized endpoints are permitted to access an MCU
- Only authorized users are permitted to access/join a conference. Authorization is pre-configured on the MCU access control system and is based on validated need-to-know as well as security clearance if applicable.

If access control measures are not implemented for all conferences hosted on a centralized MCU appliance, this is a finding.

Vulnerability Number

V-17719

Documentable

False

Rule Version

RTS-VTC 5020.00

Severity Override Guidance

Review site documentation to confirm control measures are implemented for all conferences hosted on a centralized MCU appliance as follows:
- Only authorized endpoints are permitted to access an MCU
- Only authorized users are permitted to access/join a conference. Authorization is pre-configured on the MCU access control system and is based on validated need-to-know as well as security clearance if applicable.

If access control measures are not implemented for all conferences hosted on a centralized MCU appliance, this is a finding.

Check Content Reference

M

Responsibility

Other

Target Key

1418

Comments